Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-08-20 ยท updated: 2026-08-22 ยท tags: [incident, breach] ยท confidence: medium ยท affected_sectors: [sector-technology] ยท au_impact: false

Bitdefender documented "SilkParasite", a China-based espionage campaign that has run for nearly a year against government and economic bodies across Central Asia using seven malware families, five previously unseen, with AI used in lure creation and at points in malware development. The operator's most widely used strain, DriveSilkRAT, communicates through a shared Google Drive folder rather than a dedicated command-and-control server, blending with ordinary traffic. Bitdefender tied the campaign to China via links between a malware strain and another China-based espionage group, and IP addresses used in the operation traced to Chinese telecoms; the theory is that Russia's receding influence in the region opened a vacuum China is filling economically โ€” and spying on.